cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
840
Views
13
Helpful
4
Replies

understanding of aaa authorization command level

jemekeren
Level 1
Level 1

is it true aaa authorization command level will only check tacacs server and check only associated with user. using aaa authorization must require the aaa authentication login because that is how acs know how to associate the user and command he/she allowed to execute. in other words by using only aaa authorization will confuse the router. tx for answering :)

1 Accepted Solution

Accepted Solutions

royalblues
Level 10
Level 10

AAA authentication is required for authorising a user from tacacs with a certain privilge level.

This can be done in 2 ways.

Define the Shell privilge level for each user in TACACS and have the commands for the that privilege level locally on every device.

Second and the recommended method is use shell authorization sets in TACACS. In this case the privilege level is set to 15 but the command are limited to what you have configured on the shell authorization sets.

Have a look at the attachment

HTH, rate if it does

Narayan

View solution in original post

4 Replies 4

royalblues
Level 10
Level 10

AAA authentication is required for authorising a user from tacacs with a certain privilge level.

This can be done in 2 ways.

Define the Shell privilge level for each user in TACACS and have the commands for the that privilege level locally on every device.

Second and the recommended method is use shell authorization sets in TACACS. In this case the privilege level is set to 15 but the command are limited to what you have configured on the shell authorization sets.

Have a look at the attachment

HTH, rate if it does

Narayan

Hi Narayan,

Definitely deserves rating :)

BR,

Mohammed Mahmoud.

Mohammed,

Can you share your email address.

Narayan

Hi Naryan,

Sure: mmma@gawab.com, mohammedmmoustafa@gmail.com

BR,

Mohammed Mahmoud.

Review Cisco Networking products for a $25 gift card